PT-2023-25708 · Stripe · Stripe Api

Vamsii777

·

Published

2023-07-03

·

Updated

2023-07-10

·

CVE-2023-36817

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions tktchurch/website version 0.1.0
Description The codebase for The King's Temple Church website contains a Stripe API key that was unintentionally committed and exposed. This sensitive information could be used by unauthorized parties to carry out transactions on behalf of the organization, leading to financial losses, and access sensitive customer information, resulting in privacy violations and potential legal implications. The affected component is the codebase, specifically the file(s) where the Stripe API key is embedded.
Recommendations For version 0.1.0, the maintainers plan to revoke the leaked Stripe API key immediately, generate a new one, and ensure it is not committed to the codebase. As a temporary workaround, consider restricting access to the affected file(s) where the Stripe API key is embedded until the issue is resolved.

Exploit

Fix

Information Disclosure

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-36817
GHSA-X3M6-5HMF-5X3W

Affected Products

Stripe Api